An iPhone Safari exploit linked to recent security alarms has not yet been connected to any verified digital asset theft within the scope of SlowMist’s research.
Multiple reports emerged this week advising mobile users to patch their Apple handsets immediately and warning that malicious web pages could compromise cryptographic private keys and recovery phrases, with some mentions spanning from iOS 13 all the way to iOS 26.5.
SlowMist informed Cointelegraph that it has not independently verified any individual harmed by the specific browser exploit sample it reviewed, while its most robust technical documentation covers iOS versions 18.4 through 18.6.2.
The organization noted that the “iOS 13 to 26.5” span should be viewed as speculative. “We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,” they stated.
The browser exploit recycles tactics from a previously revealed DarkSword attack vector and remains distinct from FomoPeek, another SlowMist investigation involving malicious elements embedded within an App Store application.
SlowMist finds DarkSword reuse
The Google Threat Intelligence Group (GTIG) revealed DarkSword in March, characterizing it as an iOS attack vector utilized by multiple malicious operators since at least November 2025.
SlowMist stated that MistEye, a threat intelligence division managed by its chief information security officer 23pds, initially detected the relevant activity during early May.
SlowMist published its evaluation of the WYINCC browser campaign on September 4, pointing out a malicious website promoting a complimentary virtual private server offering.
SlowMist reported that the site initiated the exploit payload upon being accessed on an iPhone via Safari, without strictly demanding any secondary action from the user.
The security flaws utilized in the sequence had already been publicly disclosed and addressed with patches by Apple, according to SlowMist.
What the Safari attack was designed to access
SlowMist discovered that the malicious browser sample it evaluated contained a module engineered to interact with Apple’s Keychain to extract and decrypt data stored therein. The script could also target application files and shared software data, potentially exposing details maintained by digital currency wallet software.
“The sample demonstrates the collection capability and the intended targets; it does not by itself prove successful extraction from every targeted wallet,” SlowMist explained.
Related: EU watchdogs warn quantum computers could pick crypto’s locks
“We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample,” SlowMist added.
SlowMist still recommends updating iOS
Despite the constraints surrounding available proof, SlowMist encouraged Apple users to install the most recent software updates provided for their hardware and to steer clear of suspicious hyperlinks.
For individuals unable to upgrade right away or facing elevated threats, SlowMist suggested evaluating Apple’s Lockdown Mode as an extra line of defense, while noting that it has not verified whether this function completely blocks the particular browser breach.
SlowMist also advised any users who suspect a wallet key or seed phrase might have been exposed to transfer their funds to a newly created wallet on an uncompromised device rather than continuing to rely on potentially vulnerable credentials.
Magazine: Asia dominates Crypto Adoption Index, Bitget’s $352M hack: Asia Express
Originally published at https://cointelegraph.com/news/no-confirmed-crypto-theft-iphone-safari-attack-slowmist?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound.